THE SHORT ANSWER

Account takeover means an unauthorized person controls an account. They may impersonate its owner, reset connected services, change recovery details or send fraudulent requests. Recovery includes securing the account, reviewing sessions and recovery methods, revoking access and warning affected contacts.

One account can be a trust and recovery hub

  • Email can receive password-reset links.
  • Messaging and social accounts can impersonate the owner.
  • Business accounts can expose customer or operational access.
  • Admin accounts can affect many connected users and services.

Recover through the provider's official process

Use a trusted device where possible, change compromised and reused credentials, review recovery email and phone details, revoke unfamiliar sessions or connected apps, and enable the strongest suitable MFA or passkey option. If access is lost, start with the provider's official recovery page.

Evidence & context: United States Federal Trade Commission

Repair the trust channel too

Tell affected contacts through another channel when fraudulent messages may have been sent. For a business account, preserve records and involve the responsible security or IT contact. Do not quietly restore access while leaving recipients to act on earlier messages.

Use the Cybersecurity module for protective controls

Read Passwords, Passkeys & Multi-Factor Authentication and How to Protect Business Accounts & Admin Access for deeper account controls.

Evidence & context: National Institute of Standards and Technology

Sources & further reading

  1. How To Recover Your Hacked Email or Social Media Account

    United States Federal Trade Commission. Defensive account-recovery guidance including reviewing recovery details and warning contacts after compromise. Exact recovery controls depend on the platform.

  2. NIST SP 800-63-4: Digital Identity Guidelines

    National Institute of Standards and Technology. The 2025 guideline distinguishes identity proofing, authentication and federation and selects assurance according to risk. It is written for United States federal systems but offers a useful conceptual reference beyond them.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗